Skip to main content

Italy AGCOM + GDPR Sender Rules

Italy (IT) sits on two regimes at once. AGCOM — the Autorità per le Garanzie nelle Comunicazioni, Italy’s communications regulator — runs an alphanumeric sender registry that pre-registers Sender IDs before carriers will pass them, and it rejects Sender IDs shorter than 3 characters. On top of that registry, GDPR (with Italian implementing data-protection guidance) layers an opt-in consent duty on marketing sends. This page expands the IT posture from the country-requirements matrix so you can close the Italian items deliberately instead of re-reading one JSON blob per launch. Italy is a tenant-owned burden. Orbit never mandates your posture — it keeps the country-rules reference that feeds the send-time gates, and it gives you the consent ledger, quiet-hours, and opt-out surfaces below. The legal posture is yours.
This page is documentation, not legal advice. AGCOM blocks unregistered alphanumeric senders at the carrier — traffic on a Sender ID with no approved IT entry does not deliver — and the opt-in duty under GDPR is enforced against the sender. Have counsel review your consent capture and FERMA handling; Orbit supplies the surfaces.

Accepted sender classes for Italy

Read the IT row of GET /compliance/country-rules?country=IT (see Country Compliance Requirements). Consolidated:

AGCOM’s alphanumeric sender registry

AGCOM is the Italian communications regulator whose sender registry drives the IT pre-registration regime. Italy moved to registry-based alphanumeric sending: a Sender ID that appears as the “from” on an SMS must be on file before the carriers pass it, and AGCOM blocks unregistered alphanumeric senders at the carrier — this is not a filtering posture you can negotiate with after the fact. The rules as they apply to your traffic:
  • Pre-registration is required. An alphanumeric Sender ID on an SMPP-routed channel into IT delivers only when the IT entry on your registration is approved. Before approval the send-time gate holds the traffic with SENDER_ID_NOT_REGISTERED or SENDER_ID_NOT_APPROVED; troubleshoot those codes with Sender-ID Registration.
  • The 3-character floor is regulatory. AGCOM rejects Sender IDs shorter than 3 characters, the same floor enforced by ANATEL, OFCOM, and BTRC — the format rule is 3–11 characters, letters, digits, space, hyphen, and underscore. A two-letter abbreviation is not a viable IT sender.
  • The 2023 onboarding cadence. AGCOM’s registry onboarding follows the intake windows the registry opened in 2023 — submissions batch into those windows rather than clearing continuously. Budget approval lead time the way Sender-ID Registration budgets pre-registration markets (days to weeks), submit well ahead of your launch date, and keep your KYC documents complete and current so a rejection-and-resubmit loop never consumes a whole window.
Tenant-owned controls that map to the AGCOM rule:

GDPR opt-in overlay on the registry

AGCOM’s registry is a sender-identity regime, not a consent regime. The GDPR consent duty applies on top of it, under the parent EU posture in the GDPR Posture Guide — registering the sender never substitutes for consent.
  • Marketing SMS into IT is opt-in. Consent must exist before dispatch; record it with sms scope per (contact, channel) through Consent Management, with lawful_basis set.
  • Evidence and withdrawal. The consent ledger is your proof-of-record — exportable through Export Consent & Suppression Records — and withdrawal lands on the suppression list every send reads.
  • Register and posture together. A fully-registered AGCOM sender with no consent records is still a non-compliant IT posture; consent with an unregistered sender never delivers. Both surfaces close the IT row.

Quiet-hours posture for Italian marketing

Italy’s marketing-convention regime — the consenso posture around GDPR — treats marketing sends at unreasonable hours as violations of the consent you captured, but unlike FR’s statutory 20:00–08:00 window there is no single codified Italian SMS window to point at. The posture is deliberate configuration, not a default Orbit sets for you. Because the IT regime grounds this in consent context rather than a fixed window, the defensible posture is: tenant quiet hours ON with a window your counsel accepts for IT marketing, paired with the consent records that make the rest of the day permissible.

Italian-language opt-out keyword handling

The Opt-Out Keyword Alias Table includes the Italian opt-out vocabulary: FERMA, CANCELLA, FINE, ANNULLA, matched with locale-insensitive case-folding and Unicode normalisation — a recipient replying ferma or Ferma. matches the same opt-out rule. The Italian opt-in counterpart (INIZIA, SÌ, SI, ISCRIVITI) re-subscribes after a prior opt-out. When an Italian opt-out fires, the suppression entry it writes is channel-scoped to all, not sms — the same propagation behaviour as the English STOP alias. A recipient’s FERMA knocks that contact off SMS, WhatsApp, and RCS simultaneously: the opt-out is a request to stop being contacted, not a request to stop SMS. If you have pruned the seeded Italian rules in the dashboard, re-add them under Messages → SMS → Opt-out Rules before launching IT traffic.

Posture-FAQ tuple for Italy

When you answer “what does Italy need?” against the Posture FAQ, the IT-specific tuple is:
  • Default quiet-hours window: platform fallback 21:00–09:00 (fail-open fallback only — configure tenant hours deliberately).
  • Opt-in required before marketing: yes (GDPR, per the GDPR Posture Guide).
  • Sender registration level: required (AGCOM pre-registration; 3-character minimum Sender-ID length).
  • Opt-out keyword family: Italian FERMA, CANCELLA, FINE, ANNULLA.
  • Official law: GDPR (EU) 2016/679; AGCOM is the Italian regulator for sender registration.

Worked configuration to a defensible IT posture

Narrowed from the generic launch checklist in Country Compliance Requirements to the IT row:
1

Look up the IT row

Call GET /compliance/country-rules?channel=sms&region=EU and read the IT row’s sender_types, registration, content_restrictions, and stop_requirement.
2

Pick a sender type

Alphanumeric Sender ID (pre-registered with AGCOM) or a long code — both are accepted in IT. Pick an alphanumeric brand of at least 3 characters.
3

Pre-flight then file the Sender ID

GET /compliance/check?sender_id=<id>&country=IT to confirm the sender is viable, then POST /compliance/sender-id-registrations with a country: "IT" entry. Budget for the AGCOM registry onboarding cadence — days to weeks, batched into the registry windows. See Sender-ID Registration.
4

Capture marketing opt-in first

Record a consent entry with sms scope before any IT marketing send; IT is opt-in under GDPR, not opt-out. See Consent Management and the GDPR Posture Guide.
5

Set tenant quiet hours deliberately

Turn on tenant quiet hours covering a window your counsel accepts for IT marketing (a conservative start is 21:00–09:00 Europe/Rome). Orbit defaults this off. See Quiet-Hours Configuration.
6

Wire the Italian opt-out family

Confirm FERMA, CANCELLA, FINE, ANNULLA are mapped into the alias table and write suppression entries. See Opt-Out Keyword Alias Table.
7

Launch

With the IT sender approved, consent captured, quiet hours set, and the Italian aliases wired, start sending.